logo

Cisco Catalyst SD-WAN Manager (CVE-2026-20122 & CVE-2026-20128) Flaws Exploited

ID: cb3bdf91-2908-5e6d-8d00-459c2cf04181

STIX ID: report--cb3bdf91-2908-5e6d-8d00-459c2cf04181

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2026-03-06

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Cisco confirmed active exploitation of two vulnerabilities in Catalyst SD-WAN Manager (CVE-2026-20122 — arbitrary file overwrite via the vManage API, and CVE-2026-20128 — DCA credential exposure). Public and third-party reporting indicates high-volume exploitation attempts and web shell deployment; Cisco provides fixed releases per version train and states there are no workarounds, so organizations should prioritize patching, restrict management/API exposure, and treat internet-facing instances as potentially compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.